
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Security & Risk Analysis
wordpress.org/plugins/uichemyConvert Figma to WordPress, Elementor, Gutenberg & Bricks. Design in Figma, Import to WordPress. 100% Editable. No Code. No Rebuild. 80,000+ users.
Is UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Safe to Use in 2026?
Generally Safe
Score 98/100UiChemy — Figma Converter for Elementor, Gutenberg and Bricks has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The uichemy plugin v4.7.0 exhibits a generally good security posture due to its adherence to several security best practices, including the consistent use of prepared statements for SQL queries and a high percentage of properly escaped output. The presence of nonce and capability checks on all identified AJAX entry points is also a positive indicator. However, the static analysis reveals a significant concern with the presence of the `unserialize` function, which, if used with user-supplied input, can lead to critical remote code execution vulnerabilities. While the taint analysis did not flag critical or high severity issues, the two identified unsanitized path flows warrant attention as they could potentially be exploited in conjunction with other weaknesses. The vulnerability history, though showing no currently unpatched CVEs, indicates a past pattern of medium severity vulnerabilities including Cross-site Scripting and Missing Authorization, suggesting a need for continued vigilance and thorough auditing.
In conclusion, while uichemy v4.7.0 demonstrates strengths in fundamental security areas like output escaping and database query sanitization, the critical risk posed by the `unserialize` function and the potential for unsanitized path flows, coupled with its historical vulnerability profile, necessitates a cautious approach. The absence of unpatched CVEs is encouraging, but the underlying code signals and past incidents suggest that further review and potentially remediation of the `unserialize` usage are crucial for a robust security posture.
Key Concerns
- Dangerous function 'unserialize' detected
- Taint analysis found unsanitized paths
- History of medium severity vulnerabilities
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
UiChemy <= 4.4.2 - Authenticated (Author+) Stored Cross-Site Scripting
UiChemy <= 4.0.0 - Missing Authorization
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Release Timeline
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Attack Surface
AJAX Handlers 10
WordPress Hooks 25
Maintenance & Trust
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Maintenance & Trust
Maintenance Signals
Community Trust
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Alternatives
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Developer Profile
8 plugins · 461K total installs
How We Detect UiChemy — Figma Converter for Elementor, Gutenberg and Bricks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uichemy/assets/css/uichemy.css/wp-content/plugins/uichemy/assets/js/uichemy-frontend.js/wp-content/plugins/uichemy/assets/js/uichemy-backend.js/wp-content/plugins/uichemy/assets/js/uich-elementor-editor.js/wp-content/plugins/uichemy/assets/js/uichemy-frontend.js/wp-content/plugins/uichemy/assets/js/uichemy-backend.js/wp-content/plugins/uichemy/assets/js/uich-elementor-editor.jsuichemy/assets/css/uichemy.css?ver=uichemy/assets/js/uichemy-frontend.js?ver=uichemy/assets/js/uichemy-backend.js?ver=uich-addons-editor-js?ver=HTML / DOM Fingerprints
uich-containeruich-itemUiChemy : Custom CSSdata-uich-iddata-uich-typewindow.uich_frontend_settings/wp-json/uich/v2/uich_store_user_data